SignorCrypto note · AI
EU AI Act Transparency Rules: What Changes in 2026
A practical checklist for AI builders, publishers and deployers after 2 August 2026

As of 20 August 2026, Article 50 of the EU AI Act is in application. It requires certain AI providers and deployers to disclose AI interactions, mark synthetic content, inform people exposed to biometric or emotion-recognition systems, and label certain deepfakes and public-interest text. The key question is not whether every AI output needs a warning, but whether a specific system or workflow falls inside an obligation—and whether the organisation can show how it complies.
This is an educational overview, not legal advice. Check the Commission’s guidance and the AI Act against the facts of each deployment.
What started on 2 August 2026
The EU AI Act applies progressively. The current EU implementation timeline lists 2 August 2026 as the milestone when most remaining rules come into force, enforcement starts for applicable rules, and Article 50 transparency rules begin to apply.
The rules mainly concern:
- direct interaction between an AI system and a person;
- synthetic or manipulated audio, image, video and text;
- emotion-recognition and biometric-categorisation systems;
- deepfakes and AI-generated or manipulated text published on matters of public interest.
A provider develops an AI system, or has it developed, and places it on the EU market or puts it into service under its name or trademark. Providers outside the EU can also be covered when the system’s output is used in the EU. A deployer uses an AI system under its authority for professional or organisational purposes.
What providers need to do
Disclose direct AI interaction
Providers of AI systems that directly interact with natural persons must design the system so people are informed that they are dealing with AI, unless it is obvious. The Commission’s FAQ describes four cumulative conditions: the system qualifies as AI, is designed for a genuine two-way exchange, communicates directly with the person, and interacts with a natural person.
Background systems, machine-to-machine communication and systems without direct contact fall outside this particular notice. Where it applies, the disclosure should be clear, distinguishable, accessible and shown from the first interaction. AI agents, chatbots and avatars are practical examples. The notice belongs in the interface and QA plan, not only in terms of service.
Make synthetic content detectable
Providers of systems that generate synthetic audio, images, video or text must ensure that generated or manipulated outputs carry effective, reliable, robust and interoperable machine-readable marks. A visible badge alone is not the same as making content detectable.
The Commission’s guidance describes limits and exceptions. Source code, short sequences of symbols, machine-to-machine outputs never exposed to people, some closed-loop industrial outputs and some standard editing workflows can fall outside the obligation. Teams should map each output type, when people first see it and which marking or provenance mechanism is used.
What deployers and publishers need to do
Inform people about biometric and emotion-recognition systems
Deployers must inform natural persons when they are exposed to an emotion-recognition or biometric-categorisation system, whether it operates in real time or after the fact. Identify who is exposed, where the system is used and when the notice is delivered. A background camera, kiosk or analytics tool is not automatically outside the rule.
Label deepfakes at first exposure
A deepfake is AI-generated or manipulated image, audio or video content that resembles an existing person, object, place, entity or event and would falsely appear authentic or truthful. Deployers must disclose it no later than first exposure.
The disclosure must be clear, distinguishable, understandable and perceivable without special technical tools. A hidden machine-readable mark alone does not satisfy this visible or audible duty. Artistic, creative, satirical or fictional works have a narrower disclosure requirement. The intended audience and whether it expects the content to be authentic are part of the Commission’s explanation.
Review public-interest text before publishing
Deployers of generative AI systems must clearly label AI-generated or manipulated text when it is published to inform the public about a matter of public interest and has not undergone human review or editorial control.
Examples include politics, public administration, justice, fundamental rights, public security, public health, environmental protection, consumer safety, and relevant economic, financial, scientific or cultural developments.
Human review is substantive examination by people with relevant knowledge and professional judgement. Editorial control means a responsible editorial entity can approve, alter or reject the substance, including fact-checking and checking sources. Spell-checking or grammar correction alone does not qualify. Publishers should keep an auditable record of who reviewed the content, what was checked and what changed.
The 2026 transition for existing systems
Article 50 applies from 2 August 2026. The Commission’s FAQ describes a limited transition for systems placed on the market before that date: for the marking and detection obligation in Article 50(2), certain providers—including providers of general-purpose AI systems generating synthetic content—must comply from 2 December 2026.
Content generated before 2 August 2026 does not need retroactive labelling, although the Commission encourages deployers to label it where possible. This is a narrow transition, not a general grace period.
What the AI Omnibus changed—and what it did not
The Digital Omnibus on AI entered into force on 27 July 2026 and changed parts of the implementation timeline. The current EU timeline moves the rules for high-risk AI systems in Annex III to 2 December 2027 and the rules for high-risk AI embedded in regulated products covered by Annex I to 2 August 2028.
That does not postpone Article 50. Transparency rules still apply from 2 August 2026. A team may have more time before some high-risk requirements apply while still needing to disclose AI interactions, mark synthetic outputs or label relevant content now.
National market-surveillance authorities will mainly enforce Article 50. The AI Office has a more limited role for systems under its supervision, and the European Data Protection Supervisor handles EU institutions. Fines can reach €15 million or 3% of total worldwide turnover for the preceding financial year, with proportionality for SMEs and small mid-cap companies.
A practical compliance plan
- Inventory every AI system, provider, deployer and audience-facing output.
- Flag direct interaction, synthetic media, biometrics, emotion recognition and public-interest publishing.
- Assign an owner for each notice, label and machine-readable marking mechanism.
- Add disclosure tests to product QA and publication checklists.
- Keep evidence of substantive human review, source checks and publication decisions.
- Recheck systems launched before 2 August 2026 against the 2 December 2026 transition.
- Revisit the mapping when guidance changes or the system’s purpose, model or output changes.
The useful mental model is simple: transparency is a product and editorial workflow, not a one-off banner.
FAQ
Does every chatbot need an AI disclosure?
Not automatically. The obligation applies when an AI system directly interacts with natural persons and it is not obvious that the person is dealing with AI. The disclosure should be clear from the first interaction.
Is a visible “AI-generated” label enough?
Not for every case. Providers may need machine-readable marking so synthetic content can be detected, while deployers have separate duties to disclose deepfakes or certain public-interest text.
Does editorial review remove the need to label public-interest AI text?
It can qualify the text for the Article 50(4) exemption when the review is substantive and there is real editorial control or responsibility. A superficial spelling or grammar check is not enough.
Are high-risk AI deadlines the same as transparency deadlines?
No. Article 50 transparency rules apply from 2 August 2026. Certain high-risk rules apply later: 2 December 2027 for Annex III systems and 2 August 2028 for high-risk AI embedded in Annex I products.
Sources
- European Commission: Guidelines on transparency obligations
- European Commission: Article 50 FAQ
- European Commission: AI Act enforcement and transparency rules
- European Commission: AI Omnibus enters into force
- EU AI Act Service Desk: Implementation timeline
If you are turning AI transparency requirements into a product, content or governance workflow, contact SignorCrypto to discuss your project.